US12008550B2ActiveUtilityA1

Post-provisioning authentication protocols

Assignee: CAPITAL ONE SERVICES LLCPriority: Apr 15, 2020Filed: Apr 15, 2020Granted: Jun 11, 2024
Est. expiryApr 15, 2040(~13.7 yrs left)· nominal 20-yr term from priority
Inventors:Erin Smith
G06Q 20/3227G06F 21/35G06F 21/44G06Q 20/3672G06Q 20/3674G06Q 20/401G06Q 20/4016G06F 2221/2111
49
PatentIndex Score
0
Cited by
14
References
20
Claims

Abstract

More effective authentication protocols for provisioning electronic devices are provided. An approval signal responsive to a provisioning request may be transmitted in real-time, such as under four seconds in certain embodiments. An authentication score for the provisioning request may be calculated even after transmitting the approval signal. In certain embodiments, information gathered from the successful provisioning of a device can be used in the authentication scoring process. Authentication scores deemed to fall below a requisite threshold may be used to suspend the provisioned device, therefore, limit the ability for the device to utilize the account, however, without withdrawing the approval or granted digital token. Certain implementations may negate the need to transmit further approvals or confirmations following determining an authentication score met a threshold.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
       1. A computerized method for authorizing an electronic device to conduct tokenized transactions, comprising:
 receiving, by a provisioning server, an electronic provisioning request requesting authorization to provision a first user device associated with a user and a first user; 
 transmitting, based on receiving the electronic provisioning request, an electronic signal providing an approval signal of the electronic provisioning request within a threshold time, the approval signal configured to authorize a third party to issue a digital token to the first user device authorizing the first user device to digitally utilize the first user account for tokenized transactions, wherein the threshold time is less than five seconds; 
 initiating, in substantially real-time and by a computer processor, a determination of an authentication score for the provisioning of the first user device, the determination comprising:
 calculating, in substantially real-time and by comparing a location associated with the user of the first user device against an origin identifier of the first user device, a first sub score; 
 calculating, in substantially real-time and by electronically comparing transactions conducted on the first user device after transmitting the approval signal of the electronic provisioning request with transactions conducted prior to the electronic provisioning request, a second sub score; 
 calculating, in substantially real-time and by determining whether the user has accessed an umbrella user account prior to receiving the electronic provisioning request, wherein the umbrella user account is an account that, once credentials are provided, allows authorized access to one or more accounts, comprising the first user account, a third sub score; and 
 calculating, using a formula based on the first sub score, the second sub score, and the third sub score, the authentication score; 
 
 determining, whether the authentication score fails to meet a predetermined threshold; and 
 transmitting, based on determining that the authentication score fails to meet the predetermined threshold, an electronic suspend message to suspend the digital token authorizing the first user device to digitally utilize the first user account for tokenized transactions. 
 
     
     
       2. The method of  claim 1 , wherein determining whether the user accessed the umbrella user account comprises determining whether the user accessed the umbrella user account on the first user device prior to the electronic provisioning request. 
     
     
       3. The method of  claim 1 , wherein it is determined that the user did not access the umbrella user account on the first user device prior to the electronic provisioning request, the method further comprising:
 determining, prior to calculating the authentication score, whether to consider additional criteria to calculate the authentication score; and 
 calculating, based on a determination to consider additional criteria to calculate the authentication score, a fourth sub score by comparing an operating system identifier of the first user device to an operating system identifier associated with the user. 
 
     
     
       4. The method of  claim 3 , wherein it is determined that the operating system identifier of the first user device does not match the operating system identifier associated with the user, the method further comprising:
 analyzing at least one location factor comprising at least one of:
 a location of the first user device upon receiving the electronic provisioning request; 
 a current location of the first user device, 
 a location of a second user device associated with the user at a point in time that the user accessed the umbrella user account, or 
 a current location of the second user device; 
 
 assigning, prior to calculating the authentication score, a weighting component to the location factor; and 
 calculating, based, at least in part, on the weighted location factor, the authentication score. 
 
     
     
       5. The method of  claim 1 , wherein determining whether the user has accessed the umbrella user account prior to the receiving the electronic provisioning request comprises utilizing only user access conducted via non-cellular networks. 
     
     
       6. The method of  claim 1 , wherein the location is determined based on the user accessing the umbrella user account at the location using a second user device. 
     
     
       7. The method of  claim 1 , wherein the location comprises a known permanent address of the user. 
     
     
       8. The method of  claim 1 , further comprising determining whether an International Mobile Equipment Identity (IMEI) of the first user device matches an IMEI associated with a prior access to the first user account. 
     
     
       9. The method of  claim 1 , wherein the electronic suspend message causes the first user device to delete the digital token. 
     
     
       10. The method of  claim 1 , wherein when electronically comparing transactions conducted on the first user device after transmitting the approval signal of the electronic provisioning request with transactions conducted prior to the electronic provisioning request, the transactions conducted prior to the electronic provisioning request were performed on at least one other device associated with the user. 
     
     
       11. The method of  claim 1 , wherein the threshold time is four seconds. 
     
     
       12. A non-transitory computer-readable medium comprising instructions that, when executed by one or more processors, cause a computing device to perform steps comprising:
 receiving an electronic provisioning request requesting authorization to provision a first user device associated with a first user account; 
 transmitting, based on receiving the electronic provisioning request, an electronic signal providing approval of the electronic provisioning request within a threshold time, the approval signal configured to authorize a third party to issue a digital token to the first user device authorizing the first user device to digitally utilize the first user account for tokenized transactions, wherein the threshold time is less than four seconds; 
 initiating, in substantially real-time and by a computer processor, a determination of an authentication score for the provisioning of the first user device, the determination comprising:
 calculating, in substantially real-time and by comparing a location associated with a user of the first user device against an origin identifier of the first user device, a first sub score; 
 calculating, in substantially real-time and by determining whether the user has accessed an umbrella user account prior to the receiving the electronic provisioning request, a second sub score; and 
 calculating, using a formula based on the first sub score and the second sub score, the authentication score; 
 
 determining, based on a determination that the authentication score satisfies a threshold requirement, not to suspend the first user account; 
 calculating, by electronically comparing transactions conducted on the first user device after transmitting the approval signal of the electronic provisioning request with transactions conducted prior to the electronic provisioning request on at least one other device associated with the user, a third sub score; 
 calculating, using a formula based on at least the third sub score and authentication score, an updated authentication score; 
 determining that the updated authentication score fails to satisfy a threshold requirement; and 
 transmitting, based on the determining, an electronic suspend message to instruct limiting utilization of the digital token on the first user device to digitally utilize the first user account for tokenized transactions. 
 
     
     
       13. The non-transitory computer-readable medium of  claim 12 , wherein the location is determined from a source other than the first user device. 
     
     
       14. The non-transitory computer-readable medium of  claim 13 , wherein the location is determined based on the user accessing with the umbrella user account at the location using a second user device. 
     
     
       15. The non-transitory computer-readable medium of  claim 12 , wherein the location comprises a known permanent address of the user. 
     
     
       16. A computing device comprising:
 at least one processor; and 
 a non-transitory computer-readable medium comprising computer-executable instructions that, when executed, cause the computing device to:
 receive an electronic provisioning request requesting authorization to provision a first user account associated with a user on a first user device; 
 transmit an electronic signal providing approval of the electronic provisioning request, the approval signal configured to authorize a third party to issue a digital token to the first user device authorizing the first user device to digitally utilize the first user account; 
 initiate, in substantially real-time and by a computer processor, a determination of an authentication score for the provisioning of the first user account on the first user device by:
 calculating, in substantially real-time and by comparing a location associated with the user of the first user device against an origin identifier of the first user device, a first sub score; 
 calculating, in substantially real-time and by electronically comparing transactions conducted on the first user device after transmitting the approval signal of the electronic provisioning request with transactions conducted prior to the electronic provisioning request on at least one other device associated with the user, a second sub score; 
 calculating, in substantially real-time and by determining whether the user has accessed an umbrella user account prior to the receiving the electronic provisioning request, a third sub score; and 
 calculating, using a formula based on the first sub score, the second sub score, and the third sub score, the authentication score; 
 
 determine, based on a determination that the authentication score satisfies a threshold requirement, that the approval was proper; 
 receive a second electronic provisioning request requesting authorization to provision a second user account associated with the user; 
 determine, within five seconds of receiving the second electronic provisioning request and based on the authentication score, whether the second electronic provisioning request is for provisioning the first user device; and 
 transmit, based on determining that the electronic provisioning request is for provisioning the first user device, an electronic signal providing approval of the second electronic provisioning request for provisioning the first user device. 
 
 
     
     
       17. The computing device of  claim 16 , wherein the non-transitory computer-readable medium further comprises computer-executable instructions that when executed by the processor cause the computing device to:
 receive a third electronic provisioning request requesting authorization to provision the second user account associated with the user; 
 determine that the third electronic provisioning request is requesting authorization to provision a second user account on a second user device; 
 calculate, by comparing a location associated with the user of the second user device against an origin identifier of the second user device, a fourth sub score; 
 calculate, using a formula based on at least the fourth sub score, the authentication score; and 
 provide, based on a determination that the authentication score satisfies a threshold requirement, an approval signal of the third electronic provisioning request. 
 
     
     
       18. The computing device of  claim 17 , wherein the approval signal of the third electronic provisioning request is done in real time. 
     
     
       19. The computing device of  claim 17 , wherein the non-transitory computer-readable medium further comprises computer-executable instructions that when executed by the processor cause the computing device to:
 receive a fourth electronic provisioning request to authorization to provision a second user account associated with the user; 
 determine that the fourth electronic provisioning request is requesting authorization to provision a second user account on a second user device; 
 recalculate, by comparing a location associated with the user of the second user device against an origin identifier of the second user device, the fourth sub score; 
 recalculate, using a formula based on at least the fourth sub score, the authentication score; and 
 transmit, based on determining that the authentication score does not meet a threshold requirement, an electronic suspend message configured to provide instructions to limit utilization of the digital token on the first user device. 
 
     
     
       20. The computing device of  claim 16 , wherein the approval of the second electronic provisioning request is done in real time.

Join the waitlist — get patent alerts

Track US12008550B2 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.